Vulnerability record · CVE-2007-2793 · published 22 May 2007
CVE-2007-2793: Geeklog ImageMagick.php remote file inclusion enables PHP code execution
Geeklog · Geeklog
Geeklog 2.x contains a remote file inclusion flaw in ImageImageMagick.php where the glConf[path_system] parameter is used to include a remote file without validation. An attacker can point that parameter at a URL they control and cause arbitrary PHP code to execute on the server. The record is old and thin, but the flaw is a direct code-execution path.
Description
PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote code execution with a public exploit and very high EPSS, though the product is legacy and not in KEV.
What it is
Geeklog 2.x contains a remote file inclusion flaw in ImageImageMagick.php where the glConf[path_system] parameter is used to include a remote file without validation. An attacker can point that parameter at a URL they control and cause arbitrary PHP code to execute on the server. The record is old and thin, but the flaw is a direct code-execution path.
Impact
An unauthenticated attacker can execute arbitrary PHP code in the web server's context, leading to full compromise of the Geeklog site and any data or credentials it can reach.
Attack surface
Reachable over the network through HTTP requests to ImageImageMagick.php with a crafted glConf[path_system] parameter; the CVSS vector indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.64497 (99.2nd percentile) and a public Exploit-DB entry (3946) exists, so exploitation is likely and tooling is available.
What to do
- Upgrade or patch Geeklog to a version that fixes the ImageImageMagick.php include issue; if no fixed release is available for the deployed branch, migrate off the affected 2.x code.
- Disable or remove the ImageMagick integration file if it is not required.
- Set allow_url_include=Off and allow_url_fopen=Off in PHP to block remote file inclusion.
- Restrict outbound network access from the web server so it cannot fetch attacker-hosted PHP files.
- Deploy a WAF rule blocking requests where glConf[path_system] contains a URL or remote scheme.
Detection
- Search web logs for requests to ImageImageMagick.php with glConf[path_system] containing http://, https://, ftp:// or other remote schemes.
- Monitor for unexpected outbound HTTP requests from the web server to unfamiliar hosts.
- Look for newly created or modified PHP files under the web root and for PHP processes spawning shell commands.
- Alert on PHP include or require errors referencing remote URLs in application logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2793 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2793), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.